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(57) Abstract: A wireless local area 
network (WLAN) includes mobile 
devices that are allowed to transfer 
wireless connections between WLAN 
subnets or channels having different 
access points. The access points connect 
to a central controller or roaming server 
that supports seamless hand-offs of 
mobile devices from one access point 
to another access point, The roaming 
server supports the reassignments of 
session data parameters from one access 
point to another (e.g., access point 
address spoofing) so that the mobile 
device can use the same parameters for 
comminicating to a. new access point 
The roaming server also supports the 
seamless handoff of a mobile device from 
one access point to another by using a 
master-slave switch technique across 
two piconets. The roaming server also 
facilitates the control of access points 
by establishing a host controller interface 
and wireless protocol stack in the roaming 
server then encapsulates host controller 
commands in a packet based network 
protocol used for communication between 
the roaming server and the access points. 
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(57) Abstract: A wireless local area 
network (WLAN) includes mobile 
devices that are allowed to transfer 
'wireless connections between WLAN 
subnets or channels having different 
access points. The access points connect 
to a central controller or roaming server 
that supports seamless hand-offs of 
mobile devices from one access point 
to another access point. The roaming 
server supports the reassignments of 
session data parameters from one access 
point to another (e.g., access point 
address spoofing) so that the mobile 
device can use the same parameters for 
comminicating to a new access point 
The roaming server also supports the 
seamless handoff of a mobile device from 
one access point to another by using a 
master-slave switch technique across 
two piconets. The roaming server also 
facilitates the control of access points 
by establishing a host controller interface 
and wireless protocol stack in the roaming 
server then encapsulates host controller 
commands in a packet based network 
protocol used for communication between 
the roaming server and the access points. 
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METHOD AND SYSTEM FOR ENABLING CENTRALIZED CONTROL OF 
WIRELESS LOCAL AREA NETWORKS 



BACKGROUND OF THE INVENTION 

Networked desktop computing is typical in both the office and home. 

5 Networking of mobile devices, such as mobile telephones, laptop computers, headsets, 
and PDA's (Personal Digital Assistants), is more difficult New wireless standards, 
such as IEEE 802.1 1 and Bluetooth (BT) are designed to enable these devices to 
communicate with each other and a wired LAN (Local Area Network). 

Bluetooth is a low cost wireless connection technology. Bluetooth is essentially 

10 a point-to-point (PPP) wireless communication technology that was developed as a 
replacement for using cable (i.e., hard wired) connections between devices. The 
Bluetooth technology is described in the Bluetooth specification, available from 
Bluetooth SIG, Inc. (see also the www.bluetooth.com web site), the entire teachings of 
which are herein incorporated by reference. This technology provides for a common 

1 5 attachment approach for different devices, and so enables mobile phones, laptops, 
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headsets, and PDA's to be easily networked in the office and eventually in public 
locations. Other standards, such as the IEEE 802.11 (Institute of Electrical & 
Electronics Engineers) and ETSI (European Telecommunications Standards Institute) 
Hff ERLAN/2, provide a generally similar wireless connection function as Bluetooth 
5 and may be used to support WLAN (wireless LAN) communications. See the IEEE 
802.1 1 "Wireless LAN Medium Access Control (MAC) and Physical Layer 
Specifications," the entire teachings of which are herein incorporated by reference. See 
also the ETSI specifications for HIPERLAN/2, such as ETSI document number TR 101 
683, "Broadband Radio Access Networks (BRAN); HDPERLAN Type 2; System 

10 Overview," the entire teachings of which are herein incorporated by reference. 

The Bluetooth technology provides for a piconet (or subnet), which is a group 
of up to eight devices, consisting of one master and a maximum of seven slaves that 
share a common hop sequence (based on a spread-spectrum frequency hopping 
technique, as is known in the art). Within the virtual channel created by a common hop 

15 sequence, the bandwidth is divided into seven time slots. One or more time slots are 
used for each master-slave communication. Amalgamating time slots increases 
capacity on that master-slave link. 

As a user moves a mobile device connected to a WLAN from one location to 
another, the mobile device must establish a new connection with a new AP (access 

20 point, such as a local area network access point) when moving out of range of the 

previous AP. Typically, this transfer from the previous AP to the new AP requires the 
breaking down of the connection with the previous AP and the establishment of a new 
connection with the new AP. 

SUMMARY OF THE INVENTION 

25 One problem with both the IEEE 802. 1 1 and Bluetooth standards has been a 

very limited or nonexistent ability for the mobile device to change its point of 
connection to the LAN (e.g., through an access point) in a seamless manner. This 
feature, known as "hand-offs" is required for many functions such as load balancing, 
improving radio link performance, and moving the mobile device inside a building 

30 without losing the network connection. 
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The Bluetooth standard version 1.1 does not support seamless hand-offs. The 
IEEE 802. 1 1 standard does have the ability for the mobile device to change its point of 
LAN connection from one AP to another on the same IP sub-net (e.g., both AP's are 
directly connected via hubs or switches, not via a router), but the hand-offtakes a 

5 number of seconds during which time there is no data flow. In addition the IEEE 

802.1 1 standard has no method for the network to force the mobile device to transfer its 
LAN connection from one AP to another. This connection transfer is required for load 
balancing and improving the radio link quality of service. 

A conventional approach, such as Bluetooth, may be modified to support hand- 

1 0 offs, but these hand-offs are typically controlled by the mobile device only, require 

changes to the software on the mobile device which stops backwards compatibility, and 
the hand-off itself is slow, which is a problem for some applications, such as voice 
communication. 

The transfer of the mobile device from one AP to another occurs typically with 
15 a delay or interruption in the communications over the WLAN to the mobile device. 
Seamless hand-offs of the mobile device from one AP to another are required both for 
continuous coverage and for QoS (Quality of Service). In the latter case mobile 
devices are moved between co-located AP's so that users can be assigned, for example, 
their own dedicated channel (i.e., given a greater bandwidth). 
20 The base version of Bluetooth has a 1 0 meter range and so if the Bluetooth 

technology is extended to enable Bluetooth to become a WLAN replacement, then an 
efficient, transparent and seamless approach to moving mobile devices from one 
piconet to another must be available. This approach must be transparent to layer 3 (i.e. : 
network and route management layer) of the network interconnection layers (e.g., as 
25 specified in the Open System Interconnection Reference Model). 

In the conventional Bluetooth approach, each member of the group (e.g., 
piconet or subnet) hops between seventy-nine different frequencies according to a 
sequence determined by the Bluetooth identifier (i.e., Bluetooth device address) of the 
master. All devices (e.g., mobile devices) have their own free running clock, but each 
30 uses a time offset to synchronize its hops with the master of a respective group. The 
master does not alter its clock. A device (e.g., mobile device) wanting to join a group 
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is initially in master mode. Such a device must detect the timing offset needed to join 
the group and then make the relevant offset at the same time as it switches into slave 
mode. This process is referred to a "joining a piconet" and is described in more detail 
in the Bluetooth specification. 
5 Once the devices are synchronized then it is possible to set up a PPP session 

from a slave (e.g., mobile device) to the master (e.g., AP), and hence link the slave 
through the master to an Ethernet LAN connected to the master. The AP normally 
terminates the PPP session, and so the data is then sent and received as level 2 IP 
packets to any suitable device, connected locally or remotely across the Internet. If one 

10 of the slaves moves beyond the range of the master, then the connection breaks and the 
mobile device must then, if possible, establish a new radio link, and PPP link with the 
most appropriate AP. Establishing a PPP session is a long process; for example, tens 
of seconds of connectivity are lost. 

One solution is to move the termination of the PPP session at a central 

15 controller (e.g., roaming server or gateway server) rather than at the AP. This means 
that when the radio connection from a mobile device to the AP is broken and re- 
established with another AP, then, as long as the switch-over between the two AP's is 
rapid, the PPP session between the mobile device and the central controller can be kept 
alive, hence avoiding the lengthy set-up process inherent in a PPP session. To 

20 implement this solution it is necessary for the mobile device to AP link to be 
seamlessly transferred from one AP to another. To achieve this all the AP'S are 
connected to a central controller (e.g., roaming server or gateway server) via an 
Ethernet LAN. Each master listens via a dedicated Bluetooth logical channel for all 
devices within range. When a master hears a new device, it relays this information 

25 back to the controller. In another case, one of the masters is maintaining a connection 
to a particular slave and signals to the controller that there is weakening reception for 
that slave as indicated by increased packet loss on the PPP link to that particular slave 
(this data is easily available from the PPP controller), and/or by another indication of 
weakening reception, such as RSSI (Received Signal Strength Indication). The 

30 controller can then look up another (or second) master with stronger reception of the 
mobile transmission and force a hand-off of the slave (i.e., transfer of the connection 
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for the mobile device from the previous AP to the new AP). This type of hand-off 
approach typically requires special client software (e.g., in the mobile device). 

It is possible to solve this problem of seamlessly moving mobile devices at layer 
3 (i.e., by using PPP). This PPP approach requires all the AP's to extend the PPP 
5 connection back to a master controller (e.g., roaming server) that terminates the PPP 
connections and switches them from one AP to another as the user moves. The 
problem with this PPP approach is scalability and speed of 'hand-off which can be 
several seconds. 

The techniques of the present invention provide two approaches that work at a 

10 lower network layer than layer 3, namely, layer 2 or the data link layer. One approach 
of the invention involves spoofing the identity of the AP. This approach involves 
assigning a separate Bluetooth identifier number to the master for each of the seven 
available time slots. The other approach of the invention involves an extension to the 
master-slave switch feature provided by the Bluetooth specification to separate a slave 

1 5 from one piconet cleanly and then attach it to another operating piconet. This master- 
slave switching is relatively simple if there is only one slave per piconet but the 
invention provides a solution that works with multiple slaves in a piconet, such as 
seven active slaves per piconet, and also when there are other parked slaves. 

Further, the present invention achieves this seamless hand-off without requiring 

20 client software, which is typically required in prior art approaches. In the present 
invention, the second master inherits the characteristics of the first master. These 
characteristics include session data, such as the Bluetooth identifier (or other WLAN 
identifier) of the access point and encryption keys, as well as the PPP magic number. 
The session data may also include an identifier for the mobile device. Also, either the 

25 clocks of both masters are synchronized, or the slave is instructed to change its 
frequency offset to match the new master. 

If there is more than one slave per master, however, this transfer of identity will 
either result in two identical masters or the first master changing its identifier and hence 
breaking its link to the other associated slaves. 

30 Thus, the present invention provides solutions to the problems indicated above 

without requiring special software (or hardware) in the mobile device (that is, changes 
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from a conventional approach are only required in the AP's and the roaming server), as 
provided for in the embodiments described below. The techniques of the invention 
provide for use of spoofing AP's by transferring unique session data (access point 
device address, hop sequence, frequency offset, and encryption key) from one master 
5 AP to another so that the mobile device is unaware of the change in master. Higher 
level variables and link sessions such as IPSEC and PPP are held at the switch (e.g., 
controller, roaming server, or gateway server). The present invention also provides for 
the assignment of a series of unique Bluetooth Device (BD) addresses to the AP, one 
for each mobile device; so that each mobile device believes it is talking to a different 

1 0 master AP when in fact the AP is changing its BD address for each master-slave link. 
BD addresses are selected that do not synchronize the associated hop patterns but 
minimize the chance of a collision. 

Thus, in one aspect, the present invention provides a method and system for 
performing a seamless handoff of a mobile device from an initial access point (e.g., 

1 5 initial AP) to a target access point (e.g., target AP). In particular, the method of the 
system (e.g., gateway application in a roaming server) includes (a) assigning session 
data to the initial access point to establish an initial connection from the mobile device 
through the initial access point to the roaming server, (b) detecting a triggering event 
that initiates a transfer of the mobile device from the initial access point to the target 

20 access point, and (c) transferring assignment of the session data from the initial access 
point to the target access point to establish a target connection from the mobile device 
through the target access point to the roaming server. This transfer of assignment is 
based on the session data and is in response to detecting that the triggering event has 
occurred, thus enabling the mobile device to use the session data to communicate with 

25 the target access point, such that the mobile device transfers seamlessly (without loss of 
connection and/or interruption of the current session with the user) from the initial 
access point to the target access point. 

In another aspect, the present invention provides for the use of the master-slave 
switch to separate a slave from a piconet cleanly by forcing it to change into a master 

30 and then to associate it with another AP before switching it back to a slave in a piconet 
associated with the second AP. The present invention provides a method and system 
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(e.g., roaming server) in a wireless local area network for performing a seamless 
handoff of a mobile device from an initial piconet having an initial access point (e.g., 
initial AP) to a target piconet having a target access point (e.g., target AP). In 
particular, the method includes assigning the mobile device associated with the initial 

5 access point a master role for the initial piconet, assigning the target access point a 
slave role in the initial piconet while the target access point retains a master role in the 
target piconet, and establishing an association of the mobile device with the target 
piconet by switching roles of the mobile device and target access point. The mobile 
device establishes the association with the target piconet as a slave of the target 

10 piconet. The target access point terminates the slave role of the target access point with 
the initial piconet, while the target access point maintains the master role in the target 
piconet, such that the mobile device transfers seamlessly from the initial piconet to the 
target piconet. 

In a further aspect, the present invention provides for splitting of the wireless 

1 5 protocol stack so that only the part required to deal with the radio frequency interface is 
located in the AP and the remainder of the stack is located in the central roaming 
server. The two parts communicate through a communications layer such as UDP 
packets sent over a LAN (e.g., Ethernet) that encapsulated host controller commands 
sent between the AP and the roaming server. This split is appropriate for all wireless 

20 protocols. The present invention provides a method and system (e.g., roaming server) 
for enabling seamless roaming of mobile devices among access points in a wireless 
local area network. In particular, the method includes (a) establishing a host controller 
interface in the roaming server, (b) encapsulating host controller commands in a 
packet-based network protocol for use in communication with access points in the 

25 wireless area network, the host controller commands directed to a connection session of 
the mobile device with the wireless local area network, and (c) exchanging the 
encapsulated host controller commands with access points in the wireless area network 
to enable a mobile device to receive the host controller commands and maintain the 
connection session while roaming among the access points. 

30 In another aspect, the present invention provides an encapsulated packet for 

encapsulating and communicating commands based on a host controller interface using 
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a packet-based network protocol. The encapsulated packet includes a host controller 
command based on the host controller interface, device address of a host exchanging 
the encapsulated packet, a sequence number for use in a series of encapsulated packets, 
and an acknowledgment number for use in acknowledging a previously transmitted 
5 encapsulated packet. 



BRIEF DESCRIPTION OF THE DRAWINGS 

The foregoing and other objects, features and advantages of the invention will 
be apparent from the following more particular description of preferred embodiments 
of the invention, as illustrated in the accompanying drawings in which like reference 
10 characters refer to the same parts throughout the different views. The drawings are not 
necessarily to scale, emphasis instead being placed upon illustrating the principles of 
the invention. 

Fig. 1 is a block diagram of a wireless local area network, including a roaming 
server, access points, and mobile device according to the present invention. 
15 Fig. 2 is a block diagram illustrating the components within the roaming server 

of Fig. 1. 

Fig. 3 is a block diagram illustrating two access points having the same access 

point device address to provide a seamless transfer for a roaming mobile device 

according to the present invention. 
20 Fig. 4 illustrates a procedure for a seamless transfer of a mobile device between 

two access points according to the present invention. 

Fig. 5 is a representation of the master/slave relationships of an initial access 

point, a mobile device, and a target access point during a master-slave switch according 

to the present invention. 
25 Fig. 6 is a flow chart of a procedure for a master/slave switch of the present 

invention. 

Fig. 7 is a block diagram of the communications interface of Fig. 2 including a 
host controller interface and a packet encapsulation module. 
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Fig. 8 is a block diagram of a server wireless protocol stack and an associated 
access point wireless protocol stack according to the present invention. 

Fig. 9 is a block diagram of the packet format of the present invention for an 
encapsulated packet for a host controller interface command based on a network based 
5 packet protocol. 

DETAILED DESCRIPTION OF THE INVENTION 

A description of preferred embodiments of the invention follows. 
Fig. 1 is a block diagram of a network 20 including a roaming server 22, access 
points 24 (e.g., 24-1, 24-2, 24-3) to a WLAN (wireless local area network) 36, and 

10 mobile device 26. The network 34 is any suitable network for connecting access 
points 24 to a roaming server, such as a hard-wired Ethernet LAN or a wireless 
network using a wireless communications protocol. In one embodiment, the network 
34 is hard-wired for part of the network 34 and wireless for one or more other parts of 
the network 34 (using one or more wireless communications protocols). The WLAN 

15 36 is a network established in accordance with a wireless technology, which the present 
invention does not require to be the same as any wireless communication protocol or 
technology used in the network 34. In general, as used herein, the term 4< wireless 
technology" refers to a Bluetooth protocol technology, a IEEE 802.1 1 protocol 
technology, a ETSI HIPERLAN/2 protocol technology, or other wireless technology 

20 suitable for a WLAN 36 (e.g., typically providing coverage over 10 to 100 meters). 

The network 34 may use such a wireless technology for all or part of the network 34, or 
may use some other suitable wireless communications protocol. The network 
connection 28 (e.g., 28-1, 28-2, and 28-3) maybe a hardwired connection, such as an 
Ethernet connection on a LAN 34, or may be a wireless connection based on a wireless 

25 technology or other suitable wireless communications protocol. The wireless 

connection 30 (e.g., 30-1 and 30-2) is a communication connection not requiring a 
hard-wired cable or link. For example, the wireless connection 30 is based on radio, 
optical, infrared, acoustic, or other non-hard-wired media. 

The roaming server 22 is any suitable computing device or digital processing 

30 device that may serve as a server in the network 20. Such a roaming server 22 can be a 
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server, a router, a bridge, a switch, or other device that may serve the purpose of a 
central controller or a gateway server in the network 20. In one embodiment, the 
roaming server 22 is not a single physical entity, but the functionality of the roaming 
server 22 (such as shown in Fig. 2) is provided by a number of physical units (e.g., 
5 computers, servers, and/or network devices) that are networked together. 

The access point 24 typically has a network connection 28 to the roaming server 
22. The access point 24 also acts as a receiving point, or connecting point, to establish 
the wireless connection 30 with each mobile device 26. In that case, the access point 
24 is equipped to recognize a wireless technology connection 30. 

10 The mobile device 26 is any suitable type of device that will support a wireless 

technology. The mobile device 26 may be a computer with wireless connection 
adapter, a PDA (personal digital assistant), or a mobile telephone such as a cellular 
telephone. The WLAN subnet or channel 38 (e.g., 38-1 and 38-2) is an access point 24 
and one or more mobile devices 26. In the case of the Bluetooth wireless technology, 

15 when there is more than one mobile device 26, then the WLAN subnet or channel 38 is 
termed a "piconet" and conventionally has up to seven mobile devices 26. When there 
is only one Bluetooth mobile device 26, then the channel 38 is known as a point to 
point link. For the present invention, even if there is more than one Bluetooth mobile 
device 26 connected to the access point 24, each Bluetooth mobile device 26 connected 

20 to the access point 24 views the channel 38 as a point to point link. The techniques of 
the present invention enable more than seven mobile devices 26 to connect to a single 
access point 24. The exact number depends on system performance. In the case of the 
IEEE 802.1 1 standard, a number of mobile devices 26 (potentially greater than seven, 
but limited by the address range within the subnet associated with that access point 24) 

25 are associated with a single access point 24. 

To summarize briefly the operation of a transfer of the data link 32 from one 
access point 24-1 to another access point 24-2, the roaming server 22 determines that a 
mobile device 26 should change its LAN connection point from access point 24-1 to 
access point 24-2 based on a triggering or initiating event. Such an event can be the 

30 moving of the mobile device 26 (e.g., when the user moves the mobile device 26 from 
one location to another), or receiving a request from a mobile device 26 or access point 
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24 to move the mobile device 26. The triggering or initiating event can also be a load 
balancing event, such as receiving an indication that one access point 24 is congested 
and another access point 24 is less congested (e.g., so that the mobile device 26 can be 
moved to another access point 24 to obtain a higher level of service, such as more 
5 bandwidth). The triggering or initiating event can also be receiving an indication of the 
quality of service level assigned to the user of the mobile device 26 (e.g., moving the 
mobile device 26 to a new access point 24 to fulfill a predefined service level for the 
user of the mobile device 26). Furthermore, the triggering event can also be a 
indication of a poor or declining quality of the connection 30 (e.g., radio link) between 

10 the mobile device 26 and an access point 24 (e.g., resulting in a transfer of the mobile 
device 26 from one access point 24-1 to another access point 24-2 that provides an 
improved quality of service for the mobile device 26 over the radio link). 

In general, the triggering event triggers a temporary or permanent handoff of the 
mobile device 26 from one access point 24-1 to another access point 24-2. The handoff 

1 5 may be due to a transient situation, such as due to temporary congestion of access point 
24-1, or temporary decline in connection quality in the initial connection 30-1 (e.g., 
radio link quality). If the handoff is temporary, the initial access point 24-1 keeps 
knowledge of the mobile device 26 for a predefined period of time (e.g., short period of 
time) so that the mobile device 26 may transfer back to the initial access point 24-1 

20 after the termination of the transient situation. The temporary handoff from one access 
point 24-1 to another access point 24-2 should occur quickly (i.e., without apparent or 
substantial interruption in the service to the mobile device 26), as is supported by the 
techniques of the present invention, as described herein. If the handoff is permanent, 
the initial access point 24-1 loses all knowledge of the mobile device 26. In general, if 

25 the handoff is temporary, but the transient situation persists, then the handoff may be 
made permanent. 

• After such a triggering or initiating event, the roaming server 22 instructs access 
points 24-1 and 24-2 to make a seamless handoff of the mobile device 26 from access 
point 24-1 to access point 24-2 at the data link level in a data link transfer 32 (that is, in 
30 the case of the Bluetooth technology, from point to point link 38-1 to point to point link 
38-2, and, in the case of the IEEE 802.11 technology, from shared radio channel 38-1 
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to shared radio channel 38-2). In making this type of transfer at the data link transfer 
level 32, the transfer is transparent to the mobile device 26 and the connection 30-1 is 
transferred or reestablished as the wireless connection 30-2 without a requirement for a 
special technology or special software in the mobile device 26 (beyond the 
conventional wireless technology required to support communications over the WLAN 



In one example of determining that a mobile device 26 should change point to 
point links 38-1 to 38-2, the roaming server 22 first receives information (i.e., the 
triggering or initiating event) from access point 24-1 currently supporting the mobile 
device 26 as the mobile device 26 moves out of the range of access point 24-1 . For 
example, this movement is indicated by a declining rate of packets (e.g., wireless 
connection packets based on the wireless technology) received at access point 24-1, 
The roaming server 22 then directs the access point 24-2 to establish a relationship or 
connection 30-2 with the subject mobile device 26. The roaming server 22 must have 
some indication from the access point 24-2 that the mobile device 26 is moving within 
range of that access point 24-2. In a preferred embodiment this indication maybe 
provided by a query broadcast over the wireless medium (e.g., query over a radio 
frequency suitable for use with the WLAN 36 based on the wireless technology) from 
access point 24-2 to detect what mobile devices 26 are within range of the access point 
24-2. When this is occurring, the roaming server 22 can instruct access points 24-1 and 
24-2 to make the seamless handoff of the mobile device 26 as a data link transfer 32. 

The roaming server 22 also determines base a triggering or initiating event 
based on congestion, quality of service level, or load balancing considerations. In this 
case, piconets 38-1 and 38-2 can be considered co-located (that is, provide wireless 
coverage to overlapping areas). For example, the mobile device 26 is within range of 
each access point 24-1 and 24-2 and may be connected, optionally, to either access 
point 24-1 or 24-2. In general, in a crowded environment such as a conference room 
there may well be multiple devices 26 desiring high speed WLAN 36 access. 

Users may choose which access point 24 to join by signaling via the loading 
variable in the SDP (service discovery protocol) for the case of the Bluetooth 
technology, and the beacon for the case of IEEE 802.1 1 technology (based on proposed 



36). 
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modifications to the IEEE 802.11 standard). Alternatively, users maybe directed to 
join a particular access point 24 by signaling via the loading variable in the radio 
protocol header or beacon. Generally, it may be desirable to introduce different levels 
of service for different users. 
5 In operation, the mobile device 26 requests service from an access point 24 by 

sending a request along with the device address of the mobile device 26. The access 
point 24 would normally respond by paging the mobile device 26 and starting the 
synchronization between the access point 24 and the mobile device 26. Instead, in the 
present invention, the access point 24 passes the request along with the device address 

10 of the mobile device 26 back to the roaming server 22 which looks up the user's service 
level data 47 in the device database 42 (see Fig. 2) and the loading on each of the 
relevant access points 24 (e.g., traffic or congestion on the subnet that the mobile 
device 26 is connected to). In the case of the Bluetooth technology, the roaming server 
22 then directs that the mobile device 26 connect to the appropriate access point 24 

1 5 (this may not be the access point 24 that received the request). For example, the mobile 
device 26 requests service from access point 24-1, but, after determining the user's 
service level, the roaming server 22 signals access point 24-2 to page the mobile device 
26 and establish a connection 30-2. In the case of the IEEE 802.1 1 technology, the 
roaming server 22 signals to all the relevant access points 24-1, 24-3 except the desired 

20 access point 24-2 to suppress their beacons. 

When the mobile device 26 moves to a new connection 38 and starts to send 
packets, the roaming server 22 looks up the mobile device 26 in the device database 42, 
and according to the user service level data 47 and WLAN loading, the roaming server 
22 might decide that the mobile device 26 should be communicating via another 

25 connection 38 that is covering that mobile device 26. That is, one access point 24 may 
offer a higher level of available bandwidth (i.e., lower level of congestion) for the 
mobile device 26 than another access point 24 that has less bandwidth available (i.e., 
higher level of congestion). For example, the preferable access point 24 may have 
fewer mobile devices 26 connected to it and thus more bandwidth available. The 

30 roaming server 22 may direct the mobile device 26 to a different access point 24. In 
either case the mobile device 26 is forced to transfer its connection 30. For example, a 
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user moves a mobile device 26 within range of both access points 24-1, 24-2, The 
mobile device 26 seeks to make a connection 30-1 to congested access point 24-1. The 
roaming server 22 thus directs the mobile device 26 to join a less congested access 
point 24-2, with the result shown by connection 30-2. Subsequently, the mobile device 
5 26 moves to the less congested access point 24-2 in a seamless handoft according to 
the techniques of the invention as described herein, without requiring re-registration 
with the roaming server 22. 

The congestion at access point 24-1 may also be due to a transient situation or 
problem, such a temporary increase in traffic by one or more of the mobile devices 26 

1 0 connected to access point 24-1 . For example, after the mobile device 26 transfers to 
access point 24-2, the transient situation (e.g., congestion) at access point 24-1 
terminates, and then the roaming server 22 directs the mobile device 26 to transfer back 
to access point 24-1. 

As described earlier, a mobile device 26 may experience declining connection 

15 quality of the connection 30-1 (e.g., radio link) to the initial access point 24-1 (also 
termed the primary access point 24-1) due to some transient situation or problem. For 
example, path attenuation occurs if a human body is in the path of the radio link 30-1 
between the mobile device 26 and the primary access point 24-1 . That is, someone 
may be sitting down or standing in the path. The connection quality declines to a 

20 comparatively low level; for example, as measured by the signal strength of the 

connection 30-1 having a lower level (e.g., lesser amplitude) than the signal strength of 
the connection 30-2. The roaming server 22 directs the mobile device 26 to transfer 
Scorn the primary access point 24-1 to a secondary access point 24-2 that has the better 
connection quality for the connection 30-2 (quality of the radio link) to the mobile 

25 device 26. This transfer may be temporary and the transient situation may terminate; 
for example, if the person obstructing the path moves out of the path. Then the 
roaming server 22 directs the mobile device 26 to transfer back from the secondary 
access point 24-2 to the primary access point 24-1. 

Fig, 2 is a block diagram illustrating the components within the roaming server 

30 22. These components include a digital processor 40, a device database 42, and a 
communications interface 44. The digital processor 40 hosts and executes a gateway 
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application 46 in the working memory of the roaming server 22. The gateway 
application 46 serves to provide for the management of the connections of the roaming 
server 22 to other devices, such as access points 24 and mobile devices 26 (typically 
through connections through access points 24). For example, the gateway application 
5 46 may instruct an access point 24-1 to perform a transfer of wireless connections 30-1 
so that the mobile device 26 can establish a new connection 30-2 with a different 
access point 24-2. In one embodiment, the gateway application 46 is implemented 
partially or totally in hardware, such as in an ASIC (application-specific integrated 
circuit). 

1 0 The device database 42 in the roaming server 22 is a memory or disk or other 

storage device that provides database and storage services for the roaming server 22, 
such as providing service level data 47 that may be assigned to a mobile device 26, or a 
user of the mobile device 26. In another example, the device database 42 can provide 
information and store information on a wireless connection 30 such as wireless 

15 connection 30-1 so that the wireless connection 30-1 may be reestablished at a different 
access point 24 such as wireless connection 30-2 (i.e., using the same communication 
parameters as wireless connection 30-1 based on information that is stored in the 
device database 42 in the roaming server 22). The session data 48 is an example of 
such information, and can include the AP device address 52 (described for Fig. 3) and 

20 other information, such as encryption information. In one embodiment, the session 
data 48 also includes a mobile device address that the roaming server 22 assigns to the 
mobile device 26. For example, when the present invention is implemented for a 
Bluetooth wireless technology, the AP device address 52 is a BD_ADDR (Bluetooth 
device) address, and the mobile device address is an AM_ADDR (active member of a 

25 piconet) address. In another example, when the present invention is implemented for 
an IEEE 802.1 1 wireless technology, the AP device address 52 is a MAC (Medium 
Access Control) address, and the mobile device address is an AID (Association 
Identifier). 

The device database 42 can be part of the roaming server 22, or may be 
30 accessed by the roaming server 22 over a communications connection or network 
connection (e.g., Internet connection). 
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A communications interface 44 of the roaming server 22 provides an interface 
to provide communications with other devices, such as a network interface to support 
network connections 28 over the LAN 34 to the access points 24. For example, the 
communications interface 44 is based on a NIC or Network Interface Card along with 
5 associated network communication software. 

In one embodiment, a computer program product 80, including a computer 
readable or usable medium (e.g., one or more CDROM's, diskettes, tapes, etc.), 
provides software instructions for the gateway application 46. The computer program 
product 80 may be installed by any suitable software installation procedure, as is well 

10 known in the art. In another embodiment, the software instructions may also be 
downloaded over a wireless connection. A computer program propagated signal 
product 82 embodied on a propagated signal on a propagation medium (e.g., a radio 
wave, an infrared wave, a laser wave, a sound wave, or an electrical wave propagated 
over the Internet or other network) provides software instructions for the gateway 

1 5 application 46. In alternate embodiments, the propagated signal is an analog carrier 
wave or digital signal carried on the propagated medium. For example, the propagated 
signal may be a digitized signal propagated over the Internet or other network. In one 
embodiment, the propagated signal is a signal that is transmitted over the propagation 
medium over a period of time, such as the instructions for a software application sent in 

20 packets over a network over a period of milliseconds, seconds, minutes, or longer. In 
another embodiment, the computer readable medium of the computer program product 
80 is a propagation medium that the computer may receive and read, such as by 
receiving the propagation medium and identifying a propagated signal embodied in the 
propagation medium, as described above for the computer program propagated signal 

25 product 82. 

Fig. 3 is a block diagram of a WLAN 50 with two access points 24-4 and 24-5 
that provide a seamless transfer for a roaming mobile device 26-2 using an access point 
device address transfer or spoofing approach according to the present invention. The 
AP device address 52 (e.g., 52-1, 52-2, 52-3, 52-4, and 52-5) is an identifier that 
30 provides an identification or address of an access point 24 in the WLAN 50. For 
example, for a Bluetooth implementation, the AP device address 52 is a Bluetooth 
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device address (BD_ADDR). In another example, for an IEEE 802. 1 1 implementation, 
the AP device address 52 is a MAC (Media Access Control) address. The 
communication channel 54 (e.g., 54-1, 54-2, 54-3, 54-4, and 54-5) is a wireless 
communication link according to a wireless technology. In one embodiment, the 
5 communication channel 54 is an example of a wireless connection 30, as illustrated in 
Fig. 1. The point to point link 57 (e.g., 57-1 and 57-2) is a WLAN subnet, typically 
supported by a respective access point 24. In one embodiment, the WLAN 50 is one 
example of the WLAN 36 of Fig. 1, and the point to point links 57-1 and 57-2 are 
examples of the point to point link 38 of Fig. 1. Communication link transfer 56 

10 indicates the transfer of the mobile device 26-2 from point to point link 57-1 to point to 
point link 57-2 using AP device address spoofing (i.e., the same AP device address 52- 
2 is used for access point 24-5 as for access point 24-4). Thus, communication channel 
54-2A (between access point 24-4 and the mobile device 26-2) is based on AP device 
address 52-2, and communication channel 54-2B (between access point 24-5 and the 

1 5 mobile device 26-2) is also based on the same AP device address 52-2. 

Fig. 4 illustrates a procedure 200 for a seamless transfer of a mobile device 26 
between two access points 24 using the AP device address spoofing of Fig. 3. In step 
202, a gateway application 46 in a roaming server 22 assigns session data 48 to the 
initial access point 24-4 to establish an initial connection 54-2 from the mobile device 

20 26-2 through the initial access point 24-4 to the roaming server 22. The session data 
48, for example, includes the AP device address 52-2, which is assigned to the initial 
access point 24-4 by the roaming server 22. In one embodiment, the roaming server 22 
assigns a mobile device address to the mobile device 26 that is also included in the 
session data 48. 

25 In step 204, a communications interface 44 of the roaming server 22 detects a 

triggering event that initiates a transfer of the mobile device 26-2 from the initial access 
point 24-4 to the target access point 24-5. This transfer is indicated by a 
communications link transfer 56 in Fig. 3. The triggering event, for example, can occur 
when the mobile device 26-2 is moved by the user from one location to another so that 

30 the mobile device 26-2 is moving out of range of the initial access point 24-4 and into 
range of the target access point 24-5. The triggering event can also be indicated by 
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congestion or the need for load balancing for the initial access point 24-4. For 
example, point to point link 57-1 may become congested in comparison to point to 
point link 57-2. Thus, the roaming server 22 initiates the transfer of the mobile device 
26-2 from the initial access point 24-4 to the target access point 24-5. The triggering 

5 event can also be indicated by a decline in connection quality for connection 54-2A. 

In step 206, the gateway application 46 transfers assignment of the session data 
48 from the initial access point 24-4 to the target access point 24-5 to establish a target 
connection 54-2 from the mobile device 26-2 through the target access point 24-5 to the 
roaming server 22 based on the session data 48. For example, the session data 48 

10 includes the AP device address 52-2, which the gateway application 46 is now 

assigning to the target access point 24-5 when it was previously assigned to the initial 
access point 24-4. The mobile device 26-2 can establish the same connection 54-2 
using the AP device address 52-2 to the target access point 24-5. Thus, the mobile 
device 26-2 is using the same session data 48 when communicating with the target 

1 5 access point 24-5 that it was using when communicating with the initial access point 
24-4. 

For the example of an implementation based on IEEE 802.1 1 wireless 
technology, to accomplish the handoff using the techniques of the present invention, 
the target access point 24-5 (secondary access point) constructs a spoof frame (based on 

20 an 802.1 1 frame) that includes the AP device address 52 (MAC address) of the initial 
access point (primary access point), the mobile device address (Association ID) of the 
mobile device 26 that was assigned by the roaming server 22 to the mobile device 26, 
as well as any data to be transferred. For example, the roaming server 22 determines 
that the connection quality of a connection 30 (radio link connection) is declining, and 

25 thus sends the next data packet to the target or secondary access point (e.g., 24-5) and 
instructs it to create the spoof frame to be sent to the mobile device 26-2. 

In another example of using the techniques of the present invention in an 
implementation based on IEEE 802.11 technology, the roaming server 22 instructs the 
target or secondary access point 24-5 to listen for a packet from the mobile device 26-2 

30 even if the packet is addressed to another access point (e.g., 24-4) having a different 
MAC address , so that packets could be returned from either access point (e.g., 24-4 or 
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24-5). Generally, each access point 24 is aware of all the packets that arrive on a radio 
channel (e.g., assuming the channel can be accessed by both access points 24-4 and 24- 
5). To avoid interference between the access points 24-4 and 24-5 if on the same 
channel, frequency hopping between the main and spoofing channels could be used. In 
5 this case, both access points 24-4 and 24-5 normally operate on different main 

channels, but the controller or roaming server 22 forces secondary or target access point 
24-5 to jump onto the same channel as the primary or initial access point 24-4 to send 
the spoofed packet. 

In a conventional IEEE 802.1 1 approach, the access point 24 changes channels 

10 in response to SNMP (Simple Network Mangement Protocol) MIB-2 (Management 
Information Base) commands, which are kept in a queue to be processed on a best 
efforts basis. Typically, such a command is executed an indeterminate amount of time 
after the command is received. The present invention provides for a direct link 
between the access point 24 and the controller or roaming server 22 that can force an 

15 immediate channel change (as soon as the current packet is sent or received). 

In a conventional IEEE 802.1 1 approach, the access point 24 uses a look up 
table to determine what to do with packets that arrive with a particular device address 
52 (MAC address). When the mobile device 26 associates with an access point 24, 
then the device address 52 (MAC address) is added to this look-up table (and removed 

20 when the mobile device 26 disassociates from that access point 24). 

In one embodiment for an IEEE 802.1 1 implementation, the present invention 
provides that the look-up table be expanded to include a new category called "watch 
ouf \ For example, the watch out category includes device addresses 52 (MAC 
addresses) and spoofing channels that the access point 24 should look out for. When 

25 the access point 24 receives packets with one of these device addresses 52 (MAC 
addresses), at a receiver signal strength (RSSI) above a certain, predefined signal 
strength then the access point 24 sends a notification packet to the controller or 
roaming server 22. 

In one embodiment for use with an IEEE 802.1 1 implementation, each mobile 
30 device 26 is synchronized with its access point 24-4, and typically changes 

synchronisation when associating with a different access point 24-5. If the access 
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points 24-4, 24-5 are on different channels, they are members of different ESS's 
(extended service sets). Then, the access points 24-4, 24-5 can be synchronized 
(because they are allowed to be synchronized because they are on different ESS's), thus 
avoiding any delay due to synchronization when the mobile device 26 is transferred 
5 form one access point 24-4 to the other access point 24-5. 

For the example of an implementation of the present invention based on 
Bluetooth wireless technology, the techniques of the present invention support 
seamless hand-offs of a mobile device 26 between two access points 24 by assigning a 
unique BD_ADDR (Bluetooth device) address for the AP device address 52 to the 

10 access point 24 for each communication channel 54 that it is supporting. In a 

conventional piconet 57 (or subnet), the communication channel 54 is a master-slave 
link. The master (e.g., access point 24) can have up to seven slaves (e.g., mobile 
devices 26), each slave following a hop pattern (based on a spread spectrum frequency 
hopping) set by the master. Each master-slave communication channel 54 occupies one 

15 or more time slots. 

In a Bluetooth device address spoofing point to point link 57, the access point 
24 has a particular AP device address 52 associated with each master-slave link (i.e., 
communication channel 54). So in case of seven slaves there are seven communication 
channels 54 (e.g., master-slave links), and the access point 24 changes its AP device 

20 address 52 for each time slot. The access point 24 does not, however, need to change 
its timing offset as this is set by the clock of the access point 24, so all the slaves (e.g., 
mobile devices 26) are in synchronization with the master (e.g., access point 24). As 
each communications channel 54 is associated with a particular AP device address 52, 
the slaves hop between frequencies in synchronization with the access point 24 but they 

25 axe no longer synchronized with each other. 

This AP device address spoofing approach of the invention has several effects, 
as described in the following paragraphs. 

It is easy to move mobile devices 26 between access points 24 by copying the 
session data 48, such as appropriate AP device address 52 and encryption codes, from 

30 one access point 24 to another access point 24. The session data 48 is the data for the 
current session between the mobile device 26 and the access point 24 based on a 
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connection 30. The session data 48 can include the AP device address 52 (e.g., 
Bluetooth address), mobile device address, hop sequence, frequency offset, and 
encryption data (e.g., encryption key or codes). The movement of session data 48, such 
as the AP device addresses 52 and encryption codes, is achieved by controlling all the 
5 access points 24 from a central roaming server 22. By having all the access points 24 
in synchronization there is no clock offset to adjust, although this issue can be resolved 
using a clock offset command (e.g., Bluetooth clock offset command). The clock offset 
command may be required because Bluetooth devices, such as access points 24 and 
mobile devices 26, normally having free running clocks. Creating a piconet 57 requires 
10 each slave to temporarily apply an offset to their clock so as to synchronize clocks with 
the master. 

The AP device address spoofing approach of the invention also permits a master 
(e.g., access point 24) to have an almost unlimited number of slaves (e.g., mobile 
devices 26) attached to it. This is possible because on each time slot there can be 

1 5 multiple slaves, each in synchronization with a different AP device address 52, and so 
hopping to a different sequence derived from the AP device address 52. 

For example, a roaming server 22 that controls the access point 24-4 can decide, • 
for each time slot, which AP device address 52-3 to give the access point 24-4. This 
AP device address 52-3 determines which mobile device 26-3 that the roaming server 

20 22 communicates with through the access point 24-4. In this example, all the other 
mobile devices 26-1 and 26-2 connected to the access point 24-4 are probably on the 
wrong frequency when the roaming server 22 transmits the packet intended for mobile 
device 26-3. Thus, the other mobile devices 26-1 and 26-2, in effect, hear nothing from 
the roaming server 22 but they continue to stay in synchronization with the access point 

25 24-4. 

Occasionally two or more mobile devices 26 receive the same packet from the 
roaming server 22. All mobile devices 26, except the one intended to receive the 
packet, reject the packet because the encryption key does not work. In one 
embodiment, it is also possible to have a number of mobile devices 26 associated with 
30 the same AP device address 52 and use different encryption keys to designate the 
appropriate recipient. The techniques of the invention enable unlimited numbers of 
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mobile devices 26 (i.e., slaves) per piconet 57 and provide an alternative means of 
paging a mobile device 26, thus eliminating any constraint on the number of parked 
devices 26 (i.e., parked slaves). 

If the transfer of the assignment of the session data 44 (step 202 in Fig. 4) is due 
to a transient situation, as described previously, the roaming server 22 may reassign the 
session data 44 to the initial access point 24-2 to re-establish the initial connection 54- 
2 A after a termination of the transient situation. Thus the roaming server 22 reassigns 
the AP device address 52-2 to the initial access point 24-4 so that the mobile device 26- 
2 can communicate with the initial access point 24-4 using the same AP device address 
52-2 that it used previously to communicate with the initial access point 24-4. 

Fig. 5 is a representation of the master-slave relationships 302, 304, 306, 308, 
310 of an initial access point 24-6, a mobile device 26-6, and a target access point 24-7 
during a master/slave switch according to the present invention. 

A master-slave switch (MSS) is a conventional, known operation in which the 
master (typically the creator of a piconet 38, such as an access point 24) and a slave 
(e.g., mobile device 26) switch roles so that the former master becomes a slave to the 
new master (former slave). The conventional switch involves a TDD (Time Division 
Duplex) switch so that the master and slave switch their TX (transmission) and RX 
(receiving) timing. The piconet 38 for the former master is based on piconet 
parameters derived from the AP device address 52 and clock of the former master. The 
conventional MSS switch leads to a newly defined piconet 38 based on piconet 
parameters derived from the AP device address 52 and clock of the new master. 

The Bluetooth baseband specification version 1.0 B (available from Bluetooth 
SIG, Inc.), describes a conventional MSS in Section 10.9.3, "Master-slave switch." 
For this discussion, the slave in the original piconet 38 is unit "A" and the master in the 
original piconet 38 is unit "B" In summary, the conventional procedure for a MSS 
switch involves: 

1 . The two units (slave A and master B) agree to trade roles so that unit A 
will be master and B will be slave. 

2. Slave A and master B perform a TDD switch between the slave A and 
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master B while retaining (temporarily) the hopping scheme of master B 
(i.e., spread-spectrum frequency hopping). 

3. Master A sends a IMP (Link Manager protocol) timing packet to slave 
B to be used in synchronizing the timing of transmissions between 

5 master A and slave B. 

4. Master A establishes new channel parameters for a new piconet 38 
(including master A and slave B) based on new piconet parameters 
derived from the address 52 and clock of master A. 

5. Master A communicates the new piconet parameters to each slave in the 
1 0 former piconet 3 8 . 



6. Master A verifies the switch of the slaves to the new piconet 38 based 

on the new piconet parameters. 
Using the techniques of the present invention, it is possible to use this master- 

1 5 slave switch to facilitate a seamless handoff of a mobile device 26 between two access 
points 24 without requiring any additional software in the mobile device 26. 

Referring to Fig. 5, access points 24-6 and 24-7 are controlled by a common 
roaming server 22. Initial access point 24-6 is the master of piconet A, and target 
access point 24-7 is the master of piconet B (see relationships 302 and 304 in Fig. 5). 

20 In one embodiment, piconet A and piconet B are examples of piconet 38 of Fig. 1. Fig. 
6 is a flow chart illustrating a procedure 400 for a master-slave switch of the present 
invention. In step 402, the roaming server 22 detects a triggering event for mobile 
device 26-6, which is currently a slave to initial access point 24-6, indicating that the 
mobile device 26-6 should transfer from the initial access point 24-6 to the target 

25 access point 24-7. For example, mobile device 26-6 is moving beyond range as 

determined by virtue of increased packet loss. In this example, the roaming server 22 
also detects that mobile device 26-6 has moved within range of target access point 24-7 
as its device identifier (e.g., Bluetooth address) can be heard by target access point 24-7 
on enquiry logical channel. As a result, the roaming server 22 desires to move mobile 

30 device 26-6 from initial access point 24-6 to target access point 24-7. At this point, the 
target access point 24-7 is a master in piconet B, and the mobile device 26-6 is still a 
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^spoofingj.aspcctoffhepresen. FotlhOT »o,e,«tasesaoB 
slave s^b aspec. of » pre- tavention my * 

Hg.offlustratetheHCIUDPp HaMnmm <9te=dona 
wra „a I Kl72is I «rtofth e payloadl22when U 
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the payload 122. Values arc defined in Table 1. 

Table! 



10 




T.evalue.O.Ol^^areln^a.^eHaUARTT^ 

control messages related <o session nutation and teat down. 
Length Body (ZLB)me»age used for acknowledgments. 

^ Conning with Fig. 9. the BD_ADDR fie.d Uo contains a hos, dev.. a^ss 

Sandn^^togeton^eup^^B.^dev.ce.denUfier.Tne 
BDADD Ridenu S es te hos, M ntroHer(,g,aoce S spoin.24orroannn g server22) 

ft atlsthesourceordestinaUo«offheencapsulatedHapacket64. 

that is tne source™ tumteeerfieM that contains 

Th.seouencenumberneldll8.sanuns.gnedl6-b.trntegerl.. 

aw encenumbereSused to ensurerehable,m.rderdehveryo t eno»psn.a,edHC. 

narkets64 Its use is described later. 

.con^meacknowledgmentn^erTO^re.iable.in-orderdehveryof 
encapsulatedHCI packets 64. Its use is described later. 
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Seq uencenumbers68andac^^ 

^U-o — ProtocoOcon^pac.ets. See Section, 8 *ehab^ 
5 DeUveryofControlMessage^^^ 

by reference. ^ incremented with the 

The sequence numbers 68 begin ax a vdmcu , 

* nac u et 64 The sequence counter is a free running 
transmissionofeveryencapsulatedpacketM. 4 

H„„evcr,inord« to ^«aUmcs sag esa K ac ta ow 1 ed ge 4 P ope,.y,«-Ptof 

tJ ♦ Thm the seauence number 68 is not incremented 
except the ZLB acknowledgment. Thus the sequence n 

after a ZLB message is sent. . 

boaeen.bod^aslidi.gwWowisi^lan^ in order todrfw,*, 

30 random transmission time delays. 
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technologies and wireiess— canon protocols othe, than the Blnetooth 
^mEESO.l.tec^andn.emimP™^ 

26 and netwo* devices (e.g., access points 24). 
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CLAIMS 



■What is claimed is: 



1. 



10 



15 



2. 

20 

3. 



4. 

25 



an initial access point to a target 

point to the target access point. 

* .rfCtaim 1 wbereinthestepofdetectingtherriggermg 

of congestion compared to a level oi c & 

, , fClaiml whereinthestepofdetectingthetriggering 
Thecomputerme^odom^^ etargetconnectio nnas a preferable level of 

connection quality compared to a level 
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connection. 



5. 



6. 

10 



15 



20 

9. 



The computer method of Claim 1 , ^ ^ 

^sesassi^anaccesspointde.ceaddress 
^ vnm^offttsessiottdalacomprises 

mobile device. 

tactadssdK access police address and 



10. 

25 



, P ; n the step of detectingme triggering 
^ecomputermethodofClaimlw^J 
eventoccursinresponsetoatranstent^uon 
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point; and further comprising a step of reassigning the session data to the initial 
access point to re-establish the initial connection after a terrnination of the 
transient situation. 

1 , The computer method of Claim 10, wherein the transient situation is one of a 
5 ' M „gesuon of me initial access point and a decline of cordon quality* the 

initial connection. 

12 A system comprising a digital processor for performing a seamless handoff of a 

local access network, the system comprising: 
10 agatewayapplicationexecutmgonmedigitalprocessorforassignmg . 

session data to the initial access point to establish an initial connection from the 
mobile device through the initial access point to a roaming server, and 

a communications interface coupled with the gateway application for 

the initial access point to the target access point; and 

the gateway application transferring assignment of the session data from 
the initial access point to the target access point to establish a target connection 
from the mobile device through the target access point to the roaming server 
based on the session data, enabling the mobile device to use the session data to 
communicate with the target access point, such that the mobUe device transfers 
seamlessly from the initial access point to the target access point. 



15 



20 



13. 



The system ofClaim 12, wherein the triggering event isbasedonroammgof 
the mobile device and wherein the communication interface detects that the 
mobile device is moving out of range of the initial access point and within range 
25 of the target access point. 

U ThesystemofClaun 12, wherein the triggering even, is based on congestion 

to wireless area network and wherein the eommunicnnons interface determmes 



1, 

i. 

V 



15. 



10 



15 



20 
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ma.thetargetaccess, 

level ofcongesnon for me initial access point. 

The sy.mofCiata 12, v.he.infteriggering even, isbased on connection 

^By-d***.—- cationsin^de^aattheurge, 
^onhaaap.fcrable.evdofconneonono.uaUVcompa^^aleve.of 

connection quality for the initial connection. 

16 . Thesy^ofClannl2,whereinu 1 e^onoa B includesana=oes S poin, 

device address and the gateway application: 

^jgns me sesaon data to to initial ac^^ 
^en.ofte^poin.a^ceadd^.on.einidalacccsspoinnand 

t^mesessiondatabyterrrtinatirstlrcas^ 
pointdeviceaddr^^^iniMaccesspointandbya^gning^ac^s^ 

device address to the target access point. 

17 The system of Claim 12, wherein: ,.„,..._ 
teiniSalconnectionisafirstversionofa .■„*..,—»— 
meini^accesspointandthemobUcd^cebasedonassigningteaccoss 

poBtde«ceaddre S stottoinitialaccesspoint-,and 

^e^ge.^onisasec.ndversionofmepoin.^p.m.unUba^ 

mobile device. 

The sysfcm of Claim 12, wherein the gateway application regisKrs the session 
data in a database. 



18. 



„. Thesys^ofClaunliwhereinmesessiondaUcon^risesmeac^poin. 
25 device address and encryption data. 
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20. 



21. 



, of Claim 12 whereinthe gateway application assigns a mobile 
acC esspoint device address andthemobile device address. 

. 0 fClaiml2wheremthecommumcationmterfacedetects^ 

triggering event occurs m response ^ 

• ♦ a-nA the eateway application reassigns the session twui 
access point; and the gateway PP , onafteraterm inationofthe 
access point to re-establish the initial connection after termin 



22. 

10 



23. 



15 



20 



25 



transient situation. 



•the!yfleinofClaim21,wne re ^maBtvm the initial 

^iniM^poin.andad^ofcoBnecUCuahV.n 



connection. 



Ac omp«.erprogr p tepedbolhi .— *- 

computer pmgram interns storw 
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10 



point to the target access point. 

• awirelesslocalareanetworkforperfonmnga 

. • dieted thereafter reassigning we 
access point is completed, uic 
20 access po rft i e for the initial piconet 

initial piconetthemaster role forth 

• • athestepofdetermir^gtoinitiatea 

«fthe target access point, 
is within range of the targ 

handoff of amobile device tro 
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W PCTAJS01/51306 

WO 02/41587 

-36- 

point and the target access point; „„Hirilal 
^^p^sorco^ed^U.e—canonn.^rface,^ 

p^rhosdngandexecu^aga^ayappUcanon^Uconng^U,: 

master role for the initial piconet; 

^te.argc.acc.sspom.aaUve^eintera.nalp.cooe* 

■ t retains a master role in the target piconet; 
while the target access point retains a nw 

10 ^ ^Ushanassociauonof^roobU.device.d^e^e. 

piconcthy^tchingro.csof^en.ohuedeviceand^^* 

so n B t ft e m obUed«i«es4ablishe S taassociation^fl«^ 

pi^asaslaveoffteurge.picone.^to^rgetaceosspou,, 

Lina^the^eroleofthe^etac^pointwittt^^ 

picone.wM^^accesspoin.rn.intainst.en^roe^e 

L^picone.suchd.atthe.ohUedevice^ersse-ess.ytan^e 

initial piconet to the target piconet. 

• rver of aaim 27, wherein the gateway application assigns the 

The roaming server oi L/iaun ±<> w 

themitialpicone -assisns the initial access point 

target access point is completed, and thereafter reasagnsm 
feth.imnalpicone.the master role for (he initial piconet 

25 ^ te a^ f ero ftt emohi.ede»ice te m te i Bti a 1 picone tttte ^ 

M ^1**. —— 

lu.eLhi.edevicetomeinina.accesspointandhyde^^u.e 

m „bile device is «uhin rang, of the target access pornt. 
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30. 



10 



15 



31 

20 



25 



toatargetpiconethavuigatargeia f ,„ M1 „dirital processor 

device establishes the associamm i„ rt fthetareet access 

• t ^dlhetaigetaccesspointtenninatestheslaveroleofthetargeta 

piconet, and the target <ua>* k mfl ; n tflins the master 

the initial picor^ to the targetpiK.net. 

„„ f„, enabling seamless roaming ofmobile devices 
Am ethodkaroanHOgserverforenabln*s rf 

e^^hingaaost — in.e^eta.n-annng^ 

protocol for use tncorom .^^toa connection session of the 

network, the host controller cornmandsduecteotoa 
...obilecevicewimthewnelesslocalareaneworband 

exchang^theencapsnla^hostcontrouercon^dswtfcac^s 

Ltrolier connnanasand^.ainu.e^nsess.on^ero^ 
among the access points. 

3 , x^-C**^^*-— ^""^ 
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commands comprises encapsulating each host controller command in an 
encapsulated packet based on the packet-based network protocol, and providing 
a device address of a host exchanging each encapsulated packet, a sequence 
number for use in a series of encapsulated packets, and an acknowledgment 
5 number for use in acknowledging a previously transmitted encapsulated packet. 

33. The method of Claim 3 1 , wherein the packet-based network protocol is a user 
datagram protocol. 

34. A roaming server comprising a digital processor for enabling seamless roaming 
of mobile devices among access points in a wireless area network, comprising: 

10 a host controller interface established in the roaming server; 

a packet encapsulation module executing on the digital processor for 
encapsulating host controller commands in a packet-based network protocol for 
use in communication with access points in the wireless area network, the host 
controller commands directed to a connection session of the mobile device 

15 with the wireless local area network; and 

a communications interface coupled with the digital processor for 
exchanging the encapsulated host controller commands with access points in 
the wireless area network to enable a mobile device to receive the host 
controller commands and maintain the connection session while roaming 

20 among the access points. 

35. The roaming server of Claim 34, wherein the packet encapsulation module 
encapsulates each host controller command in an encapsulated packet based on 
the packet-based network protocol, and the packet encapsulation module 
provides a device address of a host exchanging each encapsulated packet, a 

25 sequence number for use in a series of encapsulated packets, and an 

acknowledgment number for use in acknowledging a previously transmitted 
encapsulated packet. 
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36. The roaming server of Claim 34, wherein the packet-based network protocol is 
a user datagram protocol. 

A computer program product that includes a computer usable medium having 
computer program instructions stored thereon for enabling seamless roaming of 
mobile devices among access points in a wireless area network, such that the 
computer program instructions, when performed by a digital processor, cause 
the digital processor to: 

establish a host controller interface in a roaming server; 
encapsulate host controller commands in a packet-based network 
protocol for use in communication with access points in the wireless area 
network, the host controller commands directed to a connection session of the 
mobile device with the wireless local area network; and 

exchange the encapsulated host controller commands with access points 
in the wireless area network to enable a mobile device to receive the host 
controller commands and maintain the connection session while roaming 
among the access points. 

38. An encapsulated packet for encapsulating and communicating commands based 
on a host controller interface using a packet-based network protocol, the 
encapsulated packet comprising: 
20 a host controller command based on the host controller interface; 

device address of a host exchanging the encapsulated packet; 
a sequence number for use in a series of encapsulated packets; and 
an acknowledgment number for use in acknowledging a previously 
transmitted encapsulated packet. 



37. 

5 

10 



25 39. 



An encapsulated packet signal embodied in a propagated signal on a propagated 
medium, the encapsulated packet signal for encapsulating and communicating 
commands based on a host controller interface using a packet-based network 
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protocol, the encapsulated packet signal comprising: 

a host controller command based on the host controller interface; 
device address of a host exchanging the encapsulated packet; 
a sequence number for use in a series of encapsulated packets; and 
5 an acknowledgn fxxt number for use in acknowledging a previously 

transmitted encapsulated packet. 
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202 ASSIGN SESSION DATA TO THE INITIAL ACCESS POINT TO ESTABLISH AN 
INITIAL CONNECTION FROM THE MOBILE DEVICE THROUGH THE INITIAL 
ACCESS POINT TO A ROAMING SERVER. 



| ; 

204 DETECT A TRIGGERING EVENT (E.G., ROAMING OF THE MOBILE DEVICE) 
THAT INITIATES A TRANSFER OF THE MOBILE DEVICE FROM THE INITIAL 
ACCESS' POINT TO THE TARGET ACCESS POINT. 



• J 

206 TRANSFER ASSIGNMENT OF THE SESSION DATA (E.G., DEVICE ADDRESS) 
FROM THE INITIAL ACCESS POINT TO THE TARGET ACCESS POINT TO 
ESTABLISH A TARGET CONNECTION FROM THE MOBILE DEVICE THROUGH 
THE TARGET ACCESS POINT TO THE ROAMING SERVER BASED ON THE 
SESSION DATA. 
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402 DETECT A TRIGGERING EVENT FOR A MOBILE DEVICE INDICATING THAT 
THE DEVICE SHOULD TRANSFER FROM THE INITIAL ACCESS POINT TO THE 
TARGET ACCESS POINT. 




f 


404 INSTRUCT THE INITIAL ACCESS POINT TO START A MASTER-SLAVE 
SWITCH WITH THE MOBILE DEVICE AND PERFORM A PARTIAL SWITCH. 




f 


405 INSTRUCT THE TARGET ACCESS POINT TO CONNECT TO THE MOBILE 
DEVICE AS A SLAVE. 




f 


406 INSTRUCT THE MOBILE DEVICE TO PERFORM A COMPLETE MASTER- 
SLAVE SWITCH. 




f 



408 CANCEL THE PARTIALLY COMPLETED MASTER-SLAVE SWITCH OF THE 
INITIAL ACCESS POINT, UPON COMPLETION OF THE MASTER-SLAVE SWITCH 
OF THE MOBILE DEVICE. THIS COMPLETES THE SEAMLESS HAN DOFF OF THE 
MOBILE DEVICE FROM THE INITIAL ACCESS POINT TO THE TARGET ACCESS 
POINT. 
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